Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
CVE-2025-71380: n8n - Malicious commands can be executed on the host system
CVE-2025-71380
CVE-2025-71380
Summary
The Execute Command node in n8n allows users to run arbitrary system commands. This means attackers can use a legitimate user's access to compromise the system, steal data, or disrupt services. To protect against this, ensure all users have strong, unique credentials and limit access to the Execute Command node to only necessary users.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| n8n | n8n | <= 1.114.4 |
Original title
The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n runs. Attackers with user access or compromised credentials can exploit this no...
Original description
The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n runs. Attackers with user access or compromised credentials can exploit this node to run malicious commands, potentially leading to data exfiltration, service disruption, or complete system compromise.
mitre CVSS3.1
8.8
Vulnerability type
CWE-284
Improper Access Control
- https://github.com/n8n-io/n8n/security/advisories/GHSA-365g-vjw2-grx8 vendor-advisory
- https://www.vulncheck.com/advisories/n8n-arbitrary-command-execution-via-execute... third-party-advisory
Published: 4 Jul 2026 · Updated: 23 Jul 2026 · First seen: 4 Jul 2026